<div dir="ltr">Thank for your answer.<div>Using shibboleth as SP in front of the IDP is an interesting idea. </div><div>I have found that there is a possibility to use the ExternalAuthentication but I would have to manually handle the whole SAML flow...</div><div>The SAML Proxy login flow is clearly the cleaner solution. However, Our planning is too short and risky to do a migration from 3.4.1 to 4.x. I will check with our infrastructure however.</div><div>I will also check if by any chance this feature have been back-ported(or if I can backport it).</div><div>Thank you very much for your tips.</div><div>Regards,</div><div>Claude</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Le jeu. 16 juil. 2020 à 16:49, Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Claude Libois <<a href="mailto:clibois.work@gmail.com" target="_blank">clibois.work@gmail.com</a>> [2020-07-16 16:35]:<br>
> However, our architect claims that since version 3.3.x it's possible<br>
> that shibboleth transfer the authentication to an external IDP.<br>
<br>
Not sure what that refers to specifically but any Shibboleth IDP can<br>
be used in such a manner by protecting its SSO endpoints with a SAML<br>
SP (e.g. of the Shibboleth implementation) and hooking that SP up to<br>
the external IDP.<br>
<br>
To make that even easier IDPv4 mentions a "SAML proxy login flow"<br>
under "Noteworthy New Features" as part of its Release Notes:<br>
<a href="https://wiki.shibboleth.net/confluence/display/IDP4/ReleaseNotes" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP4/ReleaseNotes</a><br>
<br>
Since you'll have to upgrade your IDPv3 to v4 anyway before the end of<br>
the year (when support for IDPv3 will end) you might as well upgrade<br>
now and make use of that new feature.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>